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identifying, from an identified module, at least one QOS element; 
identifying, from the identified QOS element, a software resource to be tested; 
generating Java test code; 

identifying, for the software resource to he tested, a user identification and a user 
password for a user that is a member of a role intended to protect the software 
resource; and 

testing the software resource to be tested by use of the Java test code, including 
passing as parameters to the Java test code at run time the user identification and user 
password. 

2. (Currently Amended)The method of claim I wherein: 

at least one of the identified modules comprises a web module having a web module 
deployment descriptor, 

at least one of the identified QOS elements comprises a security-constraint element; 

identifying a software resource to be tested further comprises constructing, from a 
<wer>uri> element in the application deployment descriptor and from a <url-pattem> 
element in the web module deployment descriptor, a URI that identifies a software 
resource to be tested; and 

testing the software resource by use of the Java test code further comprises invoking 
the URI, wherein the invoking further comprises transmitting an HTTP request, 
wherein the HTTP request includes the URI, the user identification, and the user 
password. 
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r e c e iving an H'JLTi* r e spons e ; and 

3. (Currently Amended) The method of claim £2 wherein testing the software resource 
by use of the Java test code further comprises passing as a parameter to the Java test 
code at run time the URL 

4. (Currently Amended) The method of claim £2 wherein testing the software resource 
by use of the Java test code further comprises receiving an HTTP response. 

5. (Currently Amended) The method of claim 34 wherein testing the software resource 
by use of the Java test code further comprises determining in dependence upon the 
HTTP response whether the software resource is protected. 

6. (Original) The method of claim 1 wherein: 

at least one of the identified modules comprises an Enterprise JavaBean module 
("EJB module") having a deployment descriptor; 

at least one of the identified QOS elements comprises a <method-permission> 
restraint element; 

the <method-permission> restraint element comprises: 

a first <metho d-name> sub-element having a first <method-name> sub- 
element value, and 

a first <ejb-name> sub-element having a first <ejb-name> sub-element 
value; 

the identified software resource to be tested comprises a JavaBean method; 
identifying a software resource to be tested comprises the further steps of: 
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finding in a deployment descriptor for the identified EJB module one or 
more <enterprise-bean> elements having nested <ejb-name> sub-elements 
having values equal to the first <ejb-name> sub-element value, wherein 
each found <enterprise-bean> element comprises: 

the nested <ejb-name> sub-element, 
a <home> nested sub-element, 
a <remote> nested sub-element, and 
an <ejb-class> nested sub-element; and 

identifying, for each found <enterprise-bean> element, a method signature 
having a method name equal to the first <method-name> sub-element 
value; and 

testing the software resource by use of the Java test code comprises the further steps 
of: 

looking up the JavaBean home by use of a JNDI home name for the 
software resource; 

creating, by use of the JavaBean home, an instance of the JavaBean; and 
invoking, in the created instance, the protected JavaBean method, 

8. (Currently Amended) The method of claim 6 wherein testing the software resource by 
use of the Java test code further comprises passing as a parameter to the Java test code at 
run time the JNDI name for the JavaBean method?. 

9. (Original) The method of claim 6 wherein testing the software resource by use of the 
Java test code further comprises logging in to an application environment by use of the 
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user identification and the user password. 

10. (Original) The method of claim 6 wherein testing the software resource by use of the 
Java test code further comprises reporting whether invoking the protected JavaBean 
method succeeded. 

11. (Original) The method of claim 6 wherein identifying, for each found <enterprise- 
bean> element, a method signature having a method name equal to the first <method- 
name> sub-element value further comprises identifying, for each found <enterprise- 
bean> element, by use of Java reflection and the value of the <qb-class> element, a 
method signature having a method name equal to the first <method-narne> sub-element 
value. 

12. (Original) A system of testing a J2EE application, wherein the J2EE application 
comprises modules, the system comprising: 

means for identifying (204), from an application deployment descriptor, modules 
comprised within the J2EE application; 

means for identifying, from an identified module, at least one QOS element; 

means for identifying, from the identified QOS element, a software resource to be 
tested; 

means for generating Java test code; 

means for identifying, for the software resource to be tested, a user identification and 
a user password for a user that is a member of a role intended to protect the software 
resource; and 
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means for testing the software resource to be tested by use of the Java test code, 
including means for passing as parameters to the Java test code at run time the user 
identification and user password. 

13. (Original) The system of claim 12 wherein: 

at least one of the identified modules comprises a web module having a web module 
deployment descriptor; 

at least one of the identified QOS elements comprises a security-constraint element; 

means for identifying a software resource to be tested further comprises means for 
constructing, from a <web-uri> element in the application deployment descriptor and 
from a <url-pattern> element in the web module deployment descriptor, a URI that 
identifies a software resource to be tested; 

means for testing the software resource by use of the Java test code comprises: 

means for invoking the URI wherein the means for invoking further comprises means 
for transmitting an HTTP request, wherein the HTTP request includes the URI, the 
user identification, and the user password. 

14. (Original) The system of claim 13 wherein means for testing the software resource by 
use of the Java test code further comprises means for passing as a parameter to the Java 
test code at run time the URI. 

15. (Original) The system of claim 13 wherein means for testing the software resource by 
use of the Java test code further comprises means for receiving an HTTP response. 

16. (Currently Amended) The system of claim 4415 wherein means for testing the 
software resource by use of the Java test code further comprises means for determining in 
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dependence upon the HTTP response whether the software resource is protected. 

17. (Currently Amended) The system of claim 12 wherein: 

at least one of the identified modules comprises an Enterprise JavaBean module 
("EJB module") having a deployment descriptor; 

at least one of the identified QOS elements comprises a <method-permission> 
restraint element; 

the <method-permission> restraint element comprises: 

a first <inethod-name> sub-element having a first <method-name> sub- 
element value, and 

a first <ejb-name> sub-element having a first <ejb-name> sub-element 
value; 

the identified software resource to be tested comprises a JavaBean method; 

means for identifying a software resource to be tested comprises: 

means for finding in a deployment descriptor for the identified EJB 
module one or more <enterprise-bean> elements having nested <ejb- 
name> sub-elements having values equal to the first <ejb-name> sub- 
eLement value, wherein each found <enterprise-bean> element comprises; 

the nested <ejb-name> sub-element, 
a <home> nested sub-element, 
a <remote> nested sub-element t and 
an <ejb-class> nested sub-element; and 
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means for identifying, for each found <enterprise-bean> element, a 
method signature having a method name equal to the first <method-name> 
sub-element value; and 

means for testing the software resource by use of the Java test code comprises: 

means for looking up the JavaBean home by use of a JNDI home name for 
the software resource; 

means for creating, by use of the JavaBean home, an instance of the 
JavaBean; 

means for nvokin p invoking, in the created instance, the protected 
JavaBean method 

19. (Original) The system of claim 17 wherein means for testing the software resource by 
use of the Java test code further comprises means for passing as a parameter to the Java 
test code at run time the JNDI name for the JavaBean method^ 

20. (Original) The system of claim 17 wherein means for testing the software resource by 
use of the Java test code further comprises means for logging in to an application 
environment by use of the user identification and the user password. 

21. (Original) The system of claim 17 wherein means for testing the software resource by 
use of the Java test code further comprises means for reporting whether invoking the 
protected JavaBean method succeeded. 

22. (Original) The system of claim 17 wherein means for identifying, for each found 
<enterprise-bean> element, a method signature having a method name equal to the first 
<method-name> sub-element value further comprises means for identifying, for each 
found <enterprise-bean> element, by use of Java reflection and the value of the <ejb- 
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class> element, a method signature having a method name equal to the first <method- 
name> sub-element value. 

23. (Original) A computer program product of testing a J2EE application, wherein, the 
J2EE application comprises modules, the computer program product comprising: 

a recording medium; 

means, recorded on the recording medium, for identifying (204), from an application 
deployment descriptor, modules comprised within the J2EE application; 

means, recorded on the recording medium, for identifying, from an identified module, 
at least one QOS element; 

means, recorded on the recording medium, for identifying, from the identified QOS 
element, a software resource to be tested; 

means, recorded on the recording medium, for generating Java test code; 

means, recorded on the recording medium, for identifying, for the software resource 
to be tested, a user identification and a user password for a user that is a member of a 
role intended to protect the software resource; and 

means, recorded on the recording medium, for testing the software resource to be 
tested by use of the Java test code, including means for passing as parameters to the 
Java test code at run time the user identification and user password. 

24. (Currently Amended) The computer program product of claim 23 wherein: 

at least one of the identified modules comprises a web module having a web module 
deployment descriptor; 
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at least one of the identified QOS elements comprises a security-constraint element; 

means, recorded on the recording medium, for identifying a software resource to be 
tested further comprises means for constructing, from a <web-uri> element in the 
application deployment descriptor and from a <url-pattern> element in the web 
module deployment descriptor, a URI that identifies a software resource to be tested; 
and 

means, recorded on the recording medium, for testing the software resource by use of 
the Java test code comprises: 

means, recorded on the recording medium, for invoking the URI wherein the means 
for invoking further comprises means for transmitting an HTTP request, wherein the 
HTTP request includes the URI, the user identification, and the user password. 

25. (Original) The computer program product of claim 24 wherein means for testing the 
software resource by use of the Java test code further comprises means for passing the 
URI as a parameter to the Java test code at run time. 

26. (Original) The computer program product of claim 24 wherein means for testing the 
software resource by use of the Java test code further comprises means for receiving an 
HTTP response. 

27. (Currently Amended) The computer program product of claim 3426 wherein means 
for testing the software resource by use of the Java test code further comprises means for 
determining in dependence upon the HTTP response whether the software resource is 
protected. 

28. (Original) The computer program product of claim 23 wherein: 
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at least one of the identified modules comprises an Enterprise JavaBean module 
("EJB module") having a deployment descriptor; 

act least one of the identified QOS elements comprises a <method-permission> 
restraint element; 

the <taethod-permission> restraint element comprises: 

a first <method-name> sub-element having a first <method-name> sub- 
element value, and 

a first <ejb-name> sub-element having a first <ejb-name> sub-element 
value; 

the identified software resource to be tested comprises a JavaBean method; 

means, recorded on the recording medium, for identifying a software resource to be 
tested comprises: 

means, recorded on the recording medium, for finding in a deployment 
descriptor for the identified EJB module one or more <enterprise-bean> 
elements having nested <ejb-name> sub-elements having values equal to 
the first <ejb-name> sub-element value, wherein each found <enterprise- 
bean> element comprises: 

the nested <erjb-name> sub-element, 
a <home> nested sub-element, 
a <remote> nested sub-element, and 
an <ejb-class> nested sub-element; and 
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means, recorded on the recording medium, for identifying, for each found 
<enterprise-bearp> element, a method signature having a method name 
equal to the first <method-name> sub-element value; and 

means, recorded on the recording medium, for testing the software resource by use of 
the Java test code comprises: 

means, recorded on the recording medium, for looking up the JavaBean 
home by use of a JNDI home name for the software resource; 

means, recorded on the recording medium, for creating, by use of the 
JavaBean home, an instance of the JavaBean; 

means, recorded on the recording medium, for invoicing, in the created 
instance, the protected JavaBean method. 

29. (Currently Amended) The computer program product of claim 28 wherein means for 
testing the software resource by use of the Java test code further comprises means, 
recorded on the recording medium, for passing as a parameter to the Java test code at run 
time the JNDI name for the JavaBean methods 

30. (Original) The computer program product of claim 28 wherein means for testing the 
software resource by use of the Java test code further comprises means, recorded on the 
recording medium, for logging in to an application environment by use of the user 
identification and the user password. 

31. (Original) The computer program product of claim 28 wherein means for testing the 
software resource by use of the Java test code further comprises means, recorded on the 
recording medium, for reporting whether invoking the protected JavaBean method 
succeeded. 



13 



PAGE 15/30 ' RCVD AT 9/13/2004 3:33:05 PM [Eastern Daylight Time] * 8VR:USPTO-EFXRF-1/0 * ONIS:8729308 * CSID:5124729887 " DURATION <mm-ss):08-50 



